Malware

Win32/Kryptik.HMCA removal tips

Malware Removal

The Win32/Kryptik.HMCA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMCA virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Singapore)
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

iplogger.org
frekodi.top

How to determine Win32/Kryptik.HMCA?


File Info:

crc32: B9D2516A
md5: 29873d5f4db7060243199e49d7af8930
name: 29873D5F4DB7060243199E49D7AF8930.mlw
sha1: d8568a675e6eb74a2a2a45544c435d2e51fc6f53
sha256: 176e3a00a71c689b8239689432f5420092df00e2f497146fc7a87bb029014a69
sha512: f8fb89b79cf9d05e78c42bb7a018cb8769d311c6f1af3422953d667165414ff4108bcf83aa0f33fe88c708e113e14885b215b7b27ff302ae066c385d977a152f
ssdeep: 12288:rj33CiYKZKaJwRfyF3UQQovVmA9PHklHNC/O0o1OrDW5rot8kXjVGRuD:rWiYKWB09PwHp0o1OrD08t8GcRS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020b 0x052b

Win32/Kryptik.HMCA also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.11497
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.75e6eb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMCA
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderTrojan.GenericKD.46789573
MicroWorld-eScanTrojan.GenericKD.46789573
TencentWin32.Trojan.Injuke.Hsix
Ad-AwareTrojan.GenericKD.46789573
SophosMal/Generic-R
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.29873d5f4db70602
EmsisoftTrojan.GenericKD.46789573 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKD.46789573
AhnLab-V3CoinMiner/Win.Glupteba.R436795
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=81)
MalwarebytesTrojan.Downloader
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwoCQMMA

How to remove Win32/Kryptik.HMCA?

Win32/Kryptik.HMCA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment